Tracking for Divi Security & Risk Analysis

wordpress.org/plugins/tracking-for-divi

Track successful Divi contact form submissions with dataLayer events, Google Analytics, and Google Ads conversions.

100 active installs v1.1.1 PHP 7.4+ WP 5.3+ Updated Mar 4, 2026
datalayerdivitag-managertracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tracking for Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Tracking for Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the static analysis and vulnerability history provided, the 'tracking-for-divi' plugin v1.1.1 appears to have a strong security posture. The absence of any identified vulnerabilities in its history and the lack of critical signals in the code analysis, such as dangerous functions, raw SQL queries, or unsanitized taint flows, are highly positive indicators. The plugin also demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped outputs, minimizing the risk of common web vulnerabilities.

However, a few areas warrant attention. The complete absence of nonce checks and capability checks on all entry points, coupled with the lack of any authentication checks on AJAX handlers and permission callbacks for REST API routes (though the count is zero, the absence of checks is notable), presents a potential blind spot. While the attack surface is currently zero, if any new entry points were introduced without proper checks, they could be immediately exploitable. The plugin's reliance on 100% prepared statements and 93% escaped output is commendable, but it's crucial to maintain this rigor as the plugin evolves. The overall security is good, but the lack of explicit security checks on potential future entry points is a minor concern.

In conclusion, 'tracking-for-divi' v1.1.1 exhibits excellent security hygiene with no known vulnerabilities and robust coding practices for its current features. The main weakness lies in the absence of inherent security checks (nonces, capabilities) on its (currently non-existent) entry points. This suggests the plugin is developed with security in mind, but future development should prioritize incorporating these checks if new functionalities are added that expose entry points.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Tracking for Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tracking for Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped14 total outputs
Attack Surface

Tracking for Divi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menusrc\Admin\SettingsPage.php:50
actionadmin_initsrc\Admin\SettingsPage.php:51
actionet_pb_contact_form_submitsrc\FormSubmissionHandler.php:30
actioninitsrc\FormSubmissionHandler.php:34
actionwp_enqueue_scriptstracking-for-divi.php:45
actionplugins_loadedtracking-for-divi.php:79
actionadmin_enqueue_scriptstracking-for-divi.php:88
Maintenance & Trust

Tracking for Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads209

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Tracking for Divi Developer Profile

Kuba Serafinowski

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tracking for Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tracking-for-divi/js/dist/assets/index.js/wp-content/plugins/tracking-for-divi/js/dist/assets/index.css
Script Paths
/wp-content/plugins/tracking-for-divi/js/dist/js/client/main.ts
Version Parameters
tracking-for-divi/style.css?ver=tracking-for-divi/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
tracking-for-divi-settings-page
Data Attributes
data-tracking-for-divi-send-datalayerdata-tracking-for-divi-datalayer-variabledata-tracking-for-divi-datalayer-eventdata-tracking-for-divi-include-all-datadata-tracking-for-divi-send-gtagdata-tracking-for-divi-gtag-event+3 more
JS Globals
TRACKING_FOR_DIVI_OPTIONS
FAQ

Frequently Asked Questions about Tracking for Divi